ws_rep.exe

CA ARCserve RHA Engine

CA

It runs as a separate (within the context of its own process) windows Service named “CA ARCserve RHA Engine”.
Publisher:
CA  (signed and verified)

Product:
CA ARCserve RHA Engine

Version:
16.5.4.4050

MD5:
9260ca31c8770d1ce2d59f699c387dd7

SHA-1:
f9f2a4bee953ca966dba1ec70504726cb308ac0a

SHA-256:
021e56ec8c964b9012194352c869015e37cf7198cdebd70107f8dfb59055f141

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/24/2024 2:29:23 PM UTC  (today)

File size:
13.9 MB (14,587,904 bytes)

Product version:
16.5

Copyright:
Copyright (C) 2014 CA, Inc.

Original file name:
ws_rep.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ca\arcserve rha\engine\ws_rep.exe

Digital Signature
Signed by:

Authority:
CA

Valid from:
9/16/2010 9:29:50 AM

Valid to:
7/17/1974 3:01:34 AM

Subject:
E=support@ca.com, CN=www.ca.com, OU=www.ca.com, O=CA, L=New York City, S=New York State, C=US

Issuer:
E=support@ca.com, CN=www.ca.com, OU=www.ca.com, O=CA, L=New York City, S=New York State, C=US

Serial number:
00A2E2ACF320B6F80E

File PE Metadata
Compilation timestamp:
8/19/2014 7:40:35 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
98304:Km1mQy1W/DXrC3dKoBykAeOYzab8mp0DftEIfJ2+cribc2pXC4tKF34U5xCH0E:Km13y4Dm3CY+Fpz+cw

Entry address:
0x7B1D28

Entry point:
48, 83, EC, 28, E8, 8B, 06, 00, 00, 48, 83, C4, 28, E9, 52, FD, FF, FF, FF, 25, 58, 07, 14, 00, FF, 25, 4A, 07, 14, 00, CC, CC, E9, 39, FB, FF, FF, CC, CC, CC, 48, 83, EC, 38, 48, C7, 44, 24, 20, FE, FF, FF, FF, E8, 3E, 00, 00, 00, 90, EB, 05, 48, 8B, 44, 24, 50, 48, 83, C4, 38, C3, CC, FF, 25, 12, 07, 14, 00, FF, 25, 04, 07, 14, 00, FF, 25, F6, 06, 14, 00, FF, 25, E8, 06, 14, 00, FF, 25, DA, 06, 14, 00, FF, 25, CC, 06, 14, 00, FF, 25, BE, 06, 14, 00, FF, 25, B0, 06, 14, 00, FF, 25, A2, 06, 14, 00, FF, 25...
 
[+]

Code size:
8.9 MB (9,369,600 bytes)

Service
Display name:
CA ARCserve RHA Engine

Service name:
CAARCserveRHAEngine

Description:
Provides real-time replication and protection against data corruption for files and databases

Type:
Win32OwnProcess

Depends on:
rpcss


Scan ws_rep.exe - Powered by Reason Core Security